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DETAILED ACTION 



1 . In response to the notice of abandonment mailed on 26 September 2007, a reply 
and petition to revive the present application under 37 CFR 1 .137(b) were received on 
05 October 2007. This petition was dismissed, and a courtesy copy of an advisory 
action was provided, as of 25 March 2008. A renewed petition, reply, and request for 
continued examination were received on 27 May 2008, such petition being granted as of 
14 July 2008. 



Continued Examination Under 37 CFR 1.114 



2. A request for continued examination under 37 CFR 1.114, including the fee set 
forth in 37 CFR 1 .1 7(e), was filed in this application after final rejection. Since this 
application is eligible for continued examination under 37 CFR 1.114, and the fee set 
forth in 37 CFR 1 .17(e) has been timely paid, the finality of the previous Office action 
has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 27 May 
2008 has been entered. 

3. By the above submission, Claims 1 , 4-7, 1 2-1 5, 1 7, 1 9, 21-23, 25, and 28-35 
have been amended. Claims 3 and 24 have been canceled. No new claims have been 
added. Claims 1, 2, 4-17, 19-23, and 25-35 are currently pending in the present 
application. 
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Response to Arguments 

4. Applicant's arguments filed 27 May 2008 have been fully considered but they are 
not persuasive. 

Regarding the rejection of Claims 1-17 and 19-35 under 35 U.S.C. 103(a) as 
unpatentable over Macaulay, US Patent Application Publication 2003/0135762, in view 
of Hrastar, US Patent 7042852, and with specific reference to independent Claims 1 
and 19, Applicant argues that neither Macaulay nor Hrastar discloses the state table as 
now recited in the amended independent Claims (pages 10-12 of the present response). 
Applicant more specifically asserts that Hrastar "only records 'whether or not the device 
has been seen before and whether or not the station is unauthenticated and 
unacssoicated, authenticated, authenticated and associated or unknown state 
information associated with the wireless computer network'" (page 1 1 of the present 
response, citing Hrastar, column 29, lines 12-17) and therefore does not disclose or 
suggest "maintaining a state table on said computer, said state table storing state 
information for said mobile units, the state information including at least a MAC address 
parameter, an authentication status parameter, and a further parameter unrelated to the 
MAC address parameter and the authentication status parameter" (see pages 1 1 and 
12 of the present response). The Examiner respectfully disagrees. Although the 
relevant portion was not explicitly cited in the previous Office action, the Examiner 
submits that Macaulay and Hrastar do disclose a state table (Hrastar, column 29, lines 
5-17, the station database) storing state information including a MAC address 
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parameter (see Hrastar, column 29, lines 5-17, where the station database includes 
records with information on address, which is a MAC address, see for example column 
26, lines 41-46), an authentication status parameter (Hrastar, column 29, lines 5-17, 
where the station database includes state information corresponding to the claimed 
authentication status parameter, see column 29, lines 12-17 as previously cited), and a 
further unrelated parameter (Hrastar, column 29, lines 5-17, where the station database 
includes other parameters such as timestamps and byte counts). The Examiner 
additionally notes that there does not appear to be clear and explicit written description 
in the specification of the newly added claim limitations, as detailed below. 

Therefore, for the reasons detailed above, the Examiner maintains the rejection 
as set forth below. 

Specification 

5. The objection to the disclosure for informalities is withdrawn in light of the 
amendments to the specification. Similarly, the objection to the amendment filed 15 
December 2006 under 35 U.S.C. 132(a) for introducing new matter has been overcome 
by the amendment to the specification canceling the new matter as required. 

6. The specification is objected to as failing to provide proper antecedent basis for 
the claimed subject matter. See 37 CFR 1.75(d)(1) and MPEP § 608.01 (o). Correction 
of the following is required: There does not appear to be proper antecedent basis in the 
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specification for the new limitations in independent Claims 1 and 19 regarding the 
parameters included in the state information. See below regarding the rejection under 
35 U.S.C. 112, first paragraph, for failure to comply with the written description 
requirement for further detail. 

Claim Rejections - 35 USC §112 

7. The rejection of Claims 3-9, 12-17, and 21-35 under 35 U.S.C. 112, second 
paragraph, as indefinite is withdrawn in light of the amendments to the claims. 

8. The following is a quotation of the first paragraph of 35 U.S.C. 112: 

The specification shall contain a written description of the invention, and of the manner and process of 
making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the 
art to which it pertains, or with which it is most nearly connected, to make and use the same and shall 
set forth the best mode contemplated by the inventor of carrying out his invention. 

9. Claims 1,2, 4-17, 19-23, and 25-35 are rejected under 35 U.S.C. 112, first 
paragraph, as failing to comply with the written description requirement. The claim(s) 
contains subject matter which was not described in the specification in such a way as to 
reasonably convey to one skilled in the relevant art that the inventor(s), at the time the 
application was filed, had possession of the claimed invention. 

Specifically, independent Claims 1 and 19 have been amended to recite the 
limitation of "the state information including at least a MAC address parameter, an 
authentication status parameter, and a further parameter unrelated to the MAC address 
parameter and the authentication status parameter". Although it appears that the 
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specification does describe state information including a MAC address in paragraph 
0023 (pages 8-9 of the present specification), it is not apparent whether this description 
also provides explicit support for the now claimed "authentication status parameter" and 
further unrelated parameter. The phrase "authentication status" does not appear to be 
present in the specification, nor does the term "parameter". Further, it is not clear from 
the noted portion which, if any, of the stored state information items corresponds to the 
now claimed authentication status parameter and unrelated parameter. Additionally, 
Applicant has not pointed out where the amended claims are supported, and as detailed 
above, there does not appear to be sufficient written description of the newly added 
claim limitations in the specification as filed. See MPEP § 2163.04(I)(B). 

Claims not specifically referred to above are rejected due to their dependence on 
a rejected base claim. 

Claim Rejections - 35 USC § 103 

1 0. The following is a quotation of 35 U.S.C. 1 03(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set 
forth in section 102 of this title, if the differences between the subject matter sought to be patented and 
the prior art are such that the subject matter as a whole would have been obvious at the time the 
invention was made to a person having ordinary skill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was made. 

11. Claims 1,2, 4-17, 19-23, and 25-35 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Macaulay, US Patent Application Publication 2003/0135762, in view 
of Hrastar, US Patent 7042852. 
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In reference to Claim 1 , Macaulay discloses a method for detecting unauthorized 
attempts to access a wireless data communication system, where the method includes 
forwarding one or more packets received by an access point to a computer that 
compares the format of the packets to a format specified by a protocol (see paragraphs 
0045-0046 and 0095-0107; note also paragraphs 0032-0035 and 0042 where the 
wireless network is monitored), and signaling an alert if the packets deviate from the 
protocol specified format (see paragraphs 0049-0050). However, Macaulay does not 
explicitly disclose maintaining a state table storing state information for the mobile units, 
where the state information is also used to signal an alert. 

Hrastar discloses a method in which a state table storing state information for 
mobile units is stored (column 28, line 64-column 29, line 4, where the data store 
includes a state data store; column 29, lines 12-17), where the state information 
includes at least a MAC address parameter, an authentication status parameter, and a 
further parameter unrelated to the MAC address parameter and authentication status 
parameter (column 29, lines 5-17, where the address is a MAC address, column 26, 
lines 41-46, the "state" corresponds to the claimed authentication status, and the 
timestamps and byte counts, for example, correspond to the claimed unrelated 
parameters), and an alert is signaled if packets deviate from the stored state information 
(column 30, lines 35-43). Therefore, it would have been obvious to one of ordinary skill 
in the art to modify the method of Macaulay to include state information, in order to 
enhance network security (Hrastar, column 5, lines 21-22). 
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In reference to Claim 2, Macaulay and Hrastar further disclose a header 
message portion and comparing the format of the header portion to the protocol 
specified format (see Macaulay, the table following paragraph 0094). 

In reference to Claim 4, Macaulay and Hrastar further disclose comparing format 
of a frame control field (see Macaulay, the table following paragraph 0094). 

In reference to Claims 5 and 6, Macaulay and Hrastar further disclose 
Management and Control frames (see Macaulay, the table following paragraph 0094; 
see also paragraph 0099). 

In reference to Claims 7 and 8, Macaulay and Hrastar further disclose comparing 
a WEP flag value (see Macaulay, paragraph 0104). 

In reference to Claim 9, Macaualay and Hrastar further disclose a protocol 
version (see, for example, Macaulay, paragraph 0083). 

In reference to Claims 10 and 1 1 , Macaulay and Hrastar further disclose source 
MAC addresses that are multicast and broadcast addresses (see Macaulay, paragraphs 
0124, 0127). 

In reference to Claims 12-15 and 17, Macaulay and Hrastar further disclose 
monitoring for a possible denial of service attack (Macaulay, paragraph 0106) and that 
the packets may contain unsupported values and lengths (Macaulay, paragraph 0107, 
for example). 

In reference to Claim 16, Macaulay and Hrastar further disclose detecting a 
spoofed MAC address (Macaulay, paragraphs 0095, 0101). 
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In reference to Claim 19, Macaulay discloses a method for detecting 
unauthorized attempts to access a wireless data communication system, where the 
method includes forwarding one or more packets received by a mobile unit to a 
computer that compares the format of the packets to a format specified by a protocol 
(see paragraphs 0045-0046 and 0095-0107; note also paragraphs 0032-0035 and 0042 
where the wireless network is monitored), and signaling an alert if the packets deviate 
from the protocol specified format (see paragraphs 0049-0050). However, Macaulay 
does not explicitly disclose maintaining a state table storing state information for the 
mobile units, where the state information is also used to signal an alert. 

Hrastar discloses a method in which a state table storing state information for 
mobile units is stored (column 28, line 64-column 29, line 4, where the data store 
includes a state data store; column 29, lines 12-17), where the state information 
includes at least a MAC address parameter, an authentication status parameter, and a 
further parameter unrelated to the MAC address parameter and authentication status 
parameter (column 29, lines 5-17, where the address is a MAC address, column 26, 
lines 41-46, the "state" corresponds to the claimed authentication status, and the 
timestamps and byte counts, for example, correspond to the claimed unrelated 
parameters), and an alert is signaled if packets deviate from the stored state information 
(column 30, lines 35-43). Therefore, it would have been obvious to one of ordinary skill 
in the art to modify the method of Macaulay to include state information, in order to 
enhance network security (Hrastar, column 5, lines 21-22). 
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Claims 20-23 and 25-35 recite limitations corresponding to and similar to those 
recited in Claims 2 and 4-17, and are rejected by a similar rationale. 

Conclusion 

12. The prior art made of record and not relied upon is considered pertinent to 
applicant's disclosure. 

a. Bhagwat et al, US Patent 7216365, discloses a sniffer for wireless LAN 
security that detects unauthorized access points. 

b. Rosenberger, US Patent 7340768, discloses a system for WLAN 
monitoring and intrusion detection. 

c. Wang et al, US Patent 7426383, discloses a system for WLAN intrusion 
detection. 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Zachary A. Davis whose telephone number is (571)272- 
3870. The examiner can normally be reached on weekdays 8:30-6:00, alternate 
Fridays off. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Emmanuel Moise can be reached on (571) 272-3865. The fax phone 
number for the organization where this application or proceeding is assigned is 571- 
273-8300. 
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Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a 
USPTO Customer Service Representative or access to the automated information 
system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 



/Zachary A Davis/ 
Examiner, Art Unit 2437 



